Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GRUB2 — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in GRUB2, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known Common Weakness Enumerations associated with the GRUB2 bootloader product, focusing on security vulnerabilities within this specific software suite. It collects historical data regarding critical flaws, such as memory corruption issues, privilege escalation risks, and configuration bypasses, covering the period from initial public disclosures through to recent remediation efforts. By reviewing this information, users can track vendor advisories from Red Hat, Fedora, and other distributors, gain a deeper understanding of how specific weakness classes manifest in bootloaders, and examine the complete vulnerability history of GRUB2 to assess long-term security posture. The content is organized to help security professionals and system administrators identify patterns in defect introduction and resolution, facilitating better risk management decisions. This resource does not provide real-time monitoring but rather serves as a static reference for past incidents that have impacted system integrity during the initialization phase. Readers are encouraged to cross-reference these entries with official vendor patches and mitigation guidelines to ensure their environments remain secure against previously exploited attack vectors. The focus remains strictly on factual reporting of disclosed weaknesses without speculation or unverified claims.

Vendor: [UNKNOWN]

CVE IDTitleCVSSSeverityPublished
CVE-2025-54770 Grub2: use-after-free in net_set_vlan CWE-825 4.9 Medium2025-11-18
CVE-2025-61664 Grub2: missing unregister call for normal_exit command may lead to use-after-free CWE-825 4.9 Medium2025-11-18
CVE-2025-61663 Grub2: missing unregister call for normal commands may lead to use-after-free CWE-825 4.9 Medium2025-11-18
CVE-2025-61662 Grub2: missing unregister call for gettext command may lead to use-after-free 7.8 High2025-11-18
CVE-2025-61661 Grub2: grub2: out-of-bounds write via malicious usb device CWE-131 4.8 Medium2025-11-18
CVE-2025-54771 Grub2: use-after-free in grub_file_close() CWE-825 4.9 Medium2025-11-18
CVE-2024-56738 GNU GRUB 安全漏洞 CWE-208 7.5 -2024-12-29
CVE-2024-56737 GNU GRUB 安全漏洞 CWE-122 9.8 -2024-12-29
CVE-2022-3775 grub2 缓冲区错误漏洞 CWE-787 7.7 -2022-12-19
CVE-2022-2601 grub2 安全漏洞 CWE-122 8.6 -2022-12-14
CVE-2021-3697 grub2 缓冲区错误漏洞 CWE-787 7.0 -2022-07-06
CVE-2021-3696 grub2 缓冲区错误漏洞 CWE-787 7.0 -2022-07-06
CVE-2021-3695 grub2 缓冲区错误漏洞 CWE-787 6.4 -2022-07-06
CVE-2021-3981 grub2 安全漏洞 CWE-276 5.5 -2022-03-08
CVE-2021-3418 grub2 安全漏洞 CWE-281 6.4 -2021-03-15
CVE-2021-20233 grub2 缓冲区错误漏洞 CWE-787 8.2 -2021-03-03
CVE-2021-20225 grub2 缓冲区错误漏洞 CWE-787 6.7 -2021-03-03
CVE-2020-25632 grub2 资源管理错误漏洞 CWE-416 8.2 -2021-03-03
CVE-2020-25647 grub2 缓冲区错误漏洞 CWE-787 7.6 -2021-03-03
CVE-2020-14372 grub2 安全漏洞 CWE-184 8.2 -2021-03-03
CVE-2020-27749 grub2 缓冲区错误漏洞 CWE-121 6.7 -2021-03-03
CVE-2020-27779 grub2 安全漏洞 CWE-285 6.4 -2021-03-03
CVE-2020-14311 grub2 输入验证错误漏洞 CWE-190 5.7 Medium2020-07-31
CVE-2020-14310 grub2 输入验证错误漏洞 CWE-190 5.7 Medium2020-07-31
CVE-2019-14865 grub2 grub2-set-bootflag实用程序安全漏洞 CWE-267 7.1 -2019-11-29

All 25 known CVE vulnerabilities affecting GRUB2 with full Chinese analysis, references, and POCs where available.